Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 781 of 800|Showing 39001-39050 of 39984
everyday.com.au favicon

Everyday Rewards

everyday.com.au

66
loyalty programAustralialargeMEDIUM

The website demonstrates a strong foundation in network security and SSL/TLS implementation, scoring 100 in these areas, which ensures encrypted communication and robust network defenses. However, significant gaps exist in security headers, GDPR compliance, and adherence to the NIS2 directive, with scores ranging from 25 to 35 out of 100, exposing the business to regulatory, reputational, and operational risks. The absence of critical security headers like Content-Security-Policy and X-Frame-Options increases vulnerability to cross-site scripting and clickjacking attacks. Lack of privacy policies, cookie consent mechanisms, and third-party privacy disclosures pose serious compliance issues under GDPR, potentially resulting in fines and legal consequences. Deficiencies in information security frameworks, incident response plans, and business continuity preparations further heighten the risk of prolonged service disruptions and inadequate breach management. While email security and DNS health are relatively strong, enabling DNSSEC and configuring CAA records would enhance domain integrity and prevent abuse. Addressing these weaknesses promptly will protect customer trust, ensure regulatory compliance, and reduce the likelihood of costly security incidents.

35
25
25
85
100
85
100
loyaltyrewardsretailAustraliaWoolworths
ReactNext.jsJavaScriptAEM (Adobe Experience Manager)+2

Partner Domains:

bigw.com.au
subsidiaryanalyzing...
originenergy.com.au
partneranalyzing...

+1 more partners

2025-06-13T21:58:14.151Z
cybusinessonline.co.uk favicon

Virgin Money UK

cybusinessonline.co.uk

77
bankingUKlargeLOW

The website demonstrates a generally strong technical security foundation with high scores in email security, SSL/TLS, DNS health, and network security. However, significant gaps exist in compliance and governance areas, particularly related to GDPR and NIS2 regulations, which pose notable legal and operational risks. The absence of a cookie policy, consent banner, and incomplete privacy documentation expose the business to potential regulatory penalties and customer trust issues. Critical deficiencies in information security framework, incident response, and security policy documentation under NIS2 further elevate the risk of unmanaged security incidents and business disruption. While no critical vulnerabilities were identified, the combination of high and medium severity findings indicates an urgent need to address compliance and governance controls. Proactively remediating these issues will reduce regulatory exposure, improve stakeholder confidence, and strengthen the overall security posture. Immediate focus on policy implementation and GDPR compliance will deliver the greatest business value and risk mitigation. Ongoing monitoring of SSL certificates and DNS configurations ensures continued protection of core infrastructure components.

85
43
25
100
95
90
100
business bankingVirgin Moneybusiness accountsfinanceSME banking+1 more
jQuery 3.5.1Visual Website Optimizer (VWO)Adobe DTM (Dynamic Tag Manager)CSS Custom Properties (with fallback)+7

Partner Domains:

virginmoneyukplc.com
subsidiary74
virginmoney.com.au
sister company67

+1 more partners

2025-06-13T21:51:18.215Z
velocityfrequentflyer.com favicon

Velocity Frequent Flyer Pty Limited

velocityfrequentflyer.com

68
airline loyalty programAustralialargeMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities detected but multiple high and medium-risk issues that expose the organization to regulatory, reputational, and operational risks. Key weaknesses lie in missing essential security headers, lack of compliance with GDPR requirements, and absence of fundamental NIS2 cybersecurity governance frameworks. While foundational network and email security measures are strong, gaps in security policy documentation, incident response readiness, and privacy transparency present significant business risks. Failure to implement privacy policies and consent mechanisms may lead to regulatory fines and loss of customer trust. Additionally, missing headers like Strict-Transport-Security and Content-Security-Policy increase exposure to man-in-the-middle and cross-site scripting attacks. The organization should prioritize closing these gaps to protect sensitive information, ensure regulatory compliance, and maintain customer confidence. Immediate remediation combined with policy development and communication enhancements is essential to strengthen overall security posture.

50
25
25
100
85
85
100
frequent flyerloyalty programVirgin Australiatravelpoints+2 more
Adobe Helix RUMGoogle Fonts (Montserrat)Salesforce Embedded Service (Live Chat)New Relic Browser Agent+6

Partner Domains:

virginaustralia.com
partnerpending
flybuys.com.au
partnerpending

+1 more partners

2025-06-13T21:50:33.814Z
audible.in favicon

Audible

audible.in

67
digital media and entertainmentIndialargeMEDIUM

The website demonstrates a generally strong technical security foundation in areas such as SSL/TLS, network security, and email security, which reduces exposure to common external threats. However, significant gaps exist in security headers implementation and data privacy compliance, with critical omissions like missing Content-Security-Policy and X-Frame-Options headers that increase vulnerability to web-based attacks. The lack of GDPR compliance elements including privacy and cookie policies, consent banners, and third-party privacy disclosures poses legal and reputational risks, especially for customers in regulated regions. Additionally, the absence of a formal information security framework, incident response procedures, and security policy documentation indicates immature internal governance, which could delay threat detection and response. Medium-impact gaps in DNS security and DKIM configuration suggest room for improvement in email and domain protections. Overall, the security posture reflects a need to prioritize privacy compliance and internal security governance to mitigate business risk and maintain customer trust. Immediate remediation of high-severity issues will significantly enhance the website’s resilience against both regulatory and cyber threats.

45
25
25
85
100
85
100
audiobooksdigital mediasubscriptionentertainmentReact+1 more
ReactAmazon CloudFrontAdobe DTMAmazonUIPageJS+2

Partner Domains:

amazon.in
subsidiary69
audible.com
subsidiary67
2025-06-13T21:22:13.208Z
eventive.org favicon

Eventive

eventive.org

65
entertainmentmediumMEDIUM

The website demonstrates a moderate to low overall security posture with no critical vulnerabilities detected, but multiple high and medium risk issues that expose it to potential data breaches, compliance violations, and operational risks. Key weaknesses lie in missing essential security headers, lack of GDPR compliance artifacts such as privacy and cookie policies, and absence of fundamental NIS2 cybersecurity governance frameworks including incident response and security policy documentation. While network security, email security, SSL/TLS, and DNS configurations are relatively strong, significant improvements are needed in application-layer security and regulatory compliance to protect customer data and avoid legal penalties. The absence of cookie consent mechanisms and privacy policies poses substantial risks under GDPR regulations, potentially leading to fines and reputational damage. Furthermore, the missing security headers like Content-Security-Policy and X-Frame-Options increase susceptibility to cross-site scripting and clickjacking attacks. Addressing these vulnerabilities and compliance gaps promptly will enhance customer trust, reduce exposure to cyber threats, and ensure alignment with industry standards and regulations. Prioritizing governance and policy implementations alongside technical controls is essential for a comprehensive security posture improvement.

30
25
25
90
92
85
100
independent filmfilm festivalsticketingstreamingevent management+1 more
ReactNext.jsJavaScriptCookieConsent (from jsdelivr CDN)+4
2025-06-13T21:11:31.025Z
rednoseday.co.nz favicon

Cure Kids

rednoseday.co.nz

66
Charity / Non-profitNew ZealandmediumMEDIUM

The website demonstrates a moderate overall security posture with no critical issues detected; however, there are multiple high and medium severity gaps that present significant risk to business operations and compliance. Key vulnerabilities include lack of foundational security headers and insufficient email authentication, which increase exposure to web-based attacks and phishing risks. Compliance with GDPR and NIS2 regulations is notably weak, with missing cookie consent mechanisms, security policies, and incident response procedures that could lead to regulatory penalties and reputational damage. While network and DNS security are relatively strong, the absence of core security policies and frameworks undermines the organization's resilience against cyber threats. Immediate remediation is critical to protect sensitive customer data, ensure regulatory compliance, and maintain business continuity. Addressing these issues will also improve customer trust and reduce the likelihood of data breaches. Prioritizing security governance and visibility should be central to the remediation roadmap. Overall, the organization must advance beyond technical fixes to establish a robust security culture aligned with regulatory expectations.

65
43
25
65
87
85
100
charityfundraisingchild healthresearchnon-profit+1 more
Google Tag ManagerJavaScriptFlickity (carousel)Lazy loading images+4

Partner Domains:

curekidsventures.co.nz
subsidiarypending
2025-06-13T20:21:27.408Z